Note: This article was updated on January 13, 2025. See the update log at the bottom of the article.
On February 16, 2023, the National Credit Union Administration (NCUA) Board unanimously approved a rule titled "Cyber Incident Notification Requirements for Federally Insured Credit Unions." The rule is effective as of September 1, 2023. Let's take a look at how we got here, what the final rule says, and what credit unions need to do in response.
In July 2022, the NCUA published the proposed version of the rule. (Read a summary on our blog: The Proposed Cyber Incident Notification Requirements for Credit Unions. It does contain different information than what will be covered here.)
The proposed version had a 60-day comment period. During that window, 17 comments were submitted by credit unions, trade associations, leagues, service providers, and individual people. The NCUA provided a summary of these comments, along with responses in the final rule.
In short, the commenters provided helpful feedback and asked good questions. While the comments did not largely affect the final rule, the comment period did result in clarity and the promise of additional guidance from the NCUA, which was published on August 14, 2023.
The final rule requires federally insured credit unions to notify the NCUA as soon as possible and within 72 hours of believing the credit union experienced a reportable cyber incident. Let's break this down a bit.
The rule applies to federally insured credit unions. This includes federal credit unions, federally insured state-chartered credit unions, and all federally insured corporate credit unions.
Credit unions must notify the NCUA as soon as possible and within 72 hours. The rule explains "this is the same reporting requirement CISA must implement under the Cyber Incident Reporting Act."
The definition of "reportable cyber incident" is multi-faceted.
Part 1: It starts with the definition of a cyber incident, which the NCUA adopted as-is from NIST.
"An occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system."
Part 2: It must also be a "substantial" cyber incident. When asked about the legal definition of substantial, the NCUA quoted the Merriam-Webster Dictionary:
"Something that is important, essential, considerable in quantity, or significantly great."
Letter to Credit Unions 23-CU-07 specified that a credit union's determination of the term "substantial" could depend on several factors, such as "the size of the credit union, the type and impact of the loss, and its duration."
Part 3: It must also lead to one or more of the following.
Part 4: There is an exclusion for certain intentional events.
"A reportable cyber incident does not include any event where the cyber incident is performed in good faith by an entity in response to a specific request by the owner or operators of the system."
It is worth noting that certain events which were originally conducted "in good faith" could turn into a reportable cyber incident. For example, if a system was offline due to updates. This is a good-faith activity. If, however, the system update failed and there were unplanned, widespread outages, this would be reportable, according to the final rule (Page 7).
Due to the nature of "reportable cyber incidents," each event will need to be analyzed to determine if it qualifies. That said, to quote the final rule one last time, "anytime a FICU is unsure as to whether a cyber incident is reportable, the Board encourages the FICU to contact the agency."
That said, here is a tool to help guide you through the thought process. Follow the decision tree below to help you figure out if your situation would be best classified as a "reportable cyber incident."
Download a PDF version of the decision tree.
In addition to the final rule, the NCUA has published two letters to credit unions with guidance on the topic:
The letters explain how credit unions may notify the NCUA of a reportable cyber incident via the following methods.
The NCUA recommends five steps for implementing these new requirements.
If you are looking to take your incident management process to the next level, check out Tandem Incident Management. This product is designed to help credit unions create and manage a formal Incident Response Plan, including tracking incidents as they occur. For more information, sign up to watch a demo today.